P-660HWP-Dx User’s Guide 47
CHAPTER 11

Firewall Configuration

This chapter shows you how to enable and configure the P-660HWP-Dx firewall.

11.1 Access Methods

The web configurator is, by far, the most comprehensive firewall configuration tool your P-
660HWP-Dx has to offer. For this reason, it is recommended that you configure your firewall
using the web configurator.CLI (Command Line Interpreter) commands provide limited
configuration options and are only recommended for advanced users.

11.2 Firewall Policies Overview

Firewall rules are grouped based on the direction of travel of packets to which they apply:
By default, the P-660HWP-Dx’s stateful packet inspection allows packets traveling in the
following directions:
LAN to LAN/ Router
This allows computers on the LAN to manage the P-660HWP-Dx and communicate
between networks or subnets connected to the LAN interface.
LAN to WAN
By default, the P-660HWP-Dx’s stateful packet inspection drops packets traveling in the
following directions:
•WAN to LAN
•WAN to WAN/ Router
This prevents computers on the WAN from using the P-660HWP-Dx as a gateway to
communicate with other computers on the WAN and/or managing the P-660HWP-Dx.
You may define additional rules and sets or modify existing ones but please exercise
extreme caution in doing so.
LAN to LAN/ Router WAN to LAN
LAN to WAN WAN to WAN/ Router